Industry Category

Government Administration

Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.

2818 threat reports
Page 160 of 235

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless
Writing/Editing

Government Administration Threat Reports

Showing 19091920 / 2818 reports
CISA Flags Critical Exploited Windows Vulnerability: CVE-2026-20805
Impact· medium

CISA Flags Critical Exploited Windows Vulnerability: CVE-2026-20805

In January 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20805, a Microsoft Windows Information Disclosure Vulnerability, to its Known Exploited Vulnerabilities Catalog following evidence of active exploitation. Attackers have leveraged this vulnerability as an entry vector to access sensitive data from federal and private sector Windows machines, potentially exposing unencrypted or inadequately protected data in transit. The incident highlights the ongoing risk to government and enterprise environments from timely, opportunistic exploitation of unpatched known vulnerabilities, particularly those enabling information disclosure and lateral movement within networks. This addition to CISA’s KEV Catalog underscores intensifying efforts by cybercriminals to rapidly weaponize newly disclosed vulnerabilities, especially those impacting widely-deployed products like Microsoft Windows. Regulatory and operational pressure is mounting for organizations to accelerate remediation practices as adversaries increasingly automate exploitation processes.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
FBI Warns of Kimsuky APT’s Advanced QR Code Phishing (Quishing) Attacks
Impact· low

FBI Warns of Kimsuky APT’s Advanced QR Code Phishing (Quishing) Attacks

In early 2024, the FBI issued an alert warning of advanced quishing (QR-code phishing) campaigns conducted by North Korean state-sponsored group Kimsuky. The group targeted US and foreign government agencies, NGOs, and academic institutions by sending emails laden with malicious QR codes, which, when scanned, redirected victims to credential-harvesting sites. The campaign relied on the growing trust in QR codes and the challenges of securing email and mobile workflows. While no major data breach was announced, the intent was information theft and espionage, representing a significant risk to critical institutions’ security and reputation. This incident highlights the evolution of phishing techniques—from simple emails to advanced, device-hopping attacks using QR codes—mirroring a wider global threat trend. Organizations are urged to update security controls and awareness programs, as quishing is now surging across industries.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
GoBruteforcer Botnet Hits 50K+ Linux Servers with AI-Powered Brute Force
Impact· medium

GoBruteforcer Botnet Hits 50K+ Linux Servers with AI-Powered Brute Force

In early 2024, researchers identified a powerful new variant of the GoBruteforcer botnet actively targeting over 50,000 Linux servers worldwide. The attackers leveraged automated brute-force attacks in combination with AI-generated configurations to compromise servers running popular services such as SSH, MySQL, and Redis. Once inside, the botnet deployed additional malware to expand its network, launch further attacks, and facilitate potential data theft or service disruption, posing significant operational risks to exposed organizations. This campaign highlights the evolving nature of automated botnets, now leveraging AI tools to speed up attacks and evade detection. With Linux servers widely used in cloud and enterprise environments, the incident underscores the urgent need for improved credential hygiene, segmentation, and real-time traffic monitoring as botnets increasingly target critical infrastructure at scale.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(low)
I
Impact(medium)
Read Report
How Attackers Used Python and Cloudflare to Deploy AsyncRAT in 2024
Impact· medium

How Attackers Used Python and Cloudflare to Deploy AsyncRAT in 2024

In mid-2024, cybersecurity researchers uncovered a sophisticated phishing campaign in which threat actors leveraged Python scripts and the Cloudflare platform to distribute the AsyncRAT remote access trojan (RAT). Attackers crafted convincing email lures that enticed recipients to execute supplied Python scripts, which subsequently contacted Cloudflare infrastructure to retrieve further payloads. The use of legitimate services such as Cloudflare enabled the attackers to bypass conventional security controls, effectively concealing command-and-control traffic and deploying malware without immediate detection. The campaign facilitated remote access to victim systems, data exfiltration, and the potential for lateral movement within compromised networks. This incident underscores a continuing trend in which malicious actors abuse reputable cloud and open source ecosystems to deliver payloads and evade traditional defenses. Organizations across sectors must remain vigilant as threat groups increasingly weaponize trusted platforms and novel delivery mechanisms.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
BreachForums 2024 Breach: Cybercrime’s Biggest Exposure Yet
Impact· high

BreachForums 2024 Breach: Cybercrime’s Biggest Exposure Yet

In early May 2024, the hacker platform BreachForums was itself breached, resulting in the exposure of sensitive data belonging to over 324,000 registered users, including administrators and prominent cybercriminals. Attackers leveraged vulnerabilities in the forum’s backend to exfiltrate user registration details, encrypted password hashes, internal conversations, and potentially identifying metadata. Security researchers confirmed that the data dump contained real names, email addresses, and operational details, upending the anonymity of users who trafficked in illicit data and network access. This breach is highly significant because it marks a trend of threat actors targeting not just businesses, but the very enclaves where cybercrime is organized. It highlights a growing climate of infighting, doxxing, and exposure in the criminal underground, and signals increased scrutiny by law enforcement and vigilante hackers.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
Endesa 2024 Data Breach: Key Lessons for Energy Sector Security
Impact· high

Endesa 2024 Data Breach: Key Lessons for Energy Sector Security

In May 2024, Spanish energy giant Endesa, alongside its subsidiary Energía XXI, disclosed a data breach following unauthorized access to its internal systems by unknown attackers. The incident exposed sensitive contract-related information and personal details belonging to Endesa customers, although the company stated that no financial data was compromised. Endesa responded by promptly notifying affected clients, securing compromised systems, and initiating an investigation with law enforcement and the Spanish data protection authority. The breach underscores the growing targeting of critical infrastructure providers, where even non-financial data leaks can erode customer trust and regulatory posture. This incident is particularly relevant as critical infrastructure companies face heightened risk from threat actors leveraging lateral movement and data exfiltration techniques. With the energy sector increasingly interconnected and digitalized, organizations must prioritize zero trust strategies and robust monitoring to meet evolving compliance and regulatory demands.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(high)
Read Report
One Click IP Exposure: How Telegram Proxy Links Created a Privacy Vulnerability in 2026
Impact· medium

One Click IP Exposure: How Telegram Proxy Links Created a Privacy Vulnerability in 2026

In January 2026, security researchers revealed that Telegram users could have their real IP address exposed by clicking specially crafted proxy links disguised as regular usernames or harmless URLs. When users clicked these links in Telegram's Android or iOS apps, the app would automatically attempt to connect to the attacker-controlled proxy server, revealing the user's actual IP without further confirmation. This behavior, demonstrated across various public channels, posed targeted privacy risks, including location tracking and the potential for follow-on attacks. Telegram acknowledged the issue and stated they would introduce warnings to alert users about proxy links but did not commit to a timeline for deployment. This incident highlights a growing trend of information disclosure vulnerabilities related to messaging apps and link-based attacks, demonstrating the persistent risk of metadata and IP leaks in platforms used for privacy and circumvention. It brings renewed urgency to strengthen client security and increase user awareness, especially amid rising concerns over digital privacy and targeted cyber threats.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
CISA Orders Critical Patching After Gogs Zero-Day RCE Attacks Hit Hundreds of Servers
Impact· low

CISA Orders Critical Patching After Gogs Zero-Day RCE Attacks Hit Hundreds of Servers

In January 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued a directive to all federal agencies to urgently patch a critical remote code execution (RCE) vulnerability (CVE-2025-8110) in Gogs, a popular open-source git service, following multiple waves of active zero-day exploitation. The flaw leveraged a path traversal issue via the PutContents API, allowing authenticated attackers to overwrite files outside repositories—including SSH command configurations—to gain arbitrary code execution. At least 700 internet-facing Gogs servers showed signs of compromise, implicating risks across the federal enterprise. This incident underscores the accelerated threat posed by zero-day exploits targeting software supply chain and collaboration tools exposed to the internet. The increase in attacks against widely used developer platforms, combined with slow patch adoption and the rapid weaponization of vulnerabilities, demands renewed attention to secure configuration, real-time monitoring, and timely security updates.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(low)
Read Report
Gogs Path Traversal CVE-2025-8110: Active Exploitation Prompts CISA KEV Inclusion
Impact· low

Gogs Path Traversal CVE-2025-8110: Active Exploitation Prompts CISA KEV Inclusion

In January 2026, CISA issued an alert adding CVE-2025-8110 to its Known Exploited Vulnerabilities Catalog after confirming active exploitation of a critical path traversal vulnerability in Gogs, a popular self-hosted Git service. Threat actors leveraged this flaw to bypass directory security controls, allowing unauthorized access to sensitive files and potentially facilitating lateral movement, data exfiltration, or the deployment of malicious code in affected federal and private sector organizations. In accordance with Binding Operational Directive 22-01, Federal Civilian Executive Branch agencies were ordered to remediate this vulnerability immediately to stem ongoing exploitation risks and protect government infrastructure. The ongoing exploitation of CVE-2025-8110 highlights a growing trend of attackers targeting unmanaged or overlooked developer infrastructure for initial access. The incident underscores regulatory and operational pressure for timely vulnerability management and demonstrates the criticality of securing east-west application flows.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
US Gray Zone Cyber Operations Disrupt Venezuela’s Oil Sector in 2020
Impact· medium

US Gray Zone Cyber Operations Disrupt Venezuela’s Oil Sector in 2020

In early 2020, cyber-enabled disruptions targeted Venezuela’s state-owned oil sector amidst political upheaval and mounting international pressure. While formal attribution remains disputed, sources suggest that US-affiliated actors leveraged advanced cyber techniques—such as persistent access, supply chain vulnerabilities, and mapped system dependencies—to intermittently degrade operational capabilities and exports. The campaign unfolded as ongoing, reversible disruptions aimed at eroding economic resilience and regime stability without triggering overt conflict. These actions exemplified nation-state 'gray zone' operations, leveraging cyber tools for sustained coercion rather than momentary effect. This incident marked a shift in statecraft, signaling the integration of cyber-enabled economic interference with traditional levers like sanctions and diplomacy. It reflects a broader, rising trend of major powers using deniable, persistent cyber operations to exert pressure on adversarial infrastructure while remaining below the threshold of conventional military escalation.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(medium)
Read Report
BreachForums 2025 Breach: 324,000 Accounts and PGP Keys Leaked in Cybercrime Forum Incident
Impact· high

BreachForums 2025 Breach: 324,000 Accounts and PGP Keys Leaked in Cybercrime Forum Incident

In August 2025, BreachForums—the notorious hacking forum—suffered a major data leak when an unsecured backup of its user database was exposed online during site restoration activities. Threat actors, including a site impersonating the ShinyHunters gang, published the database containing nearly 324,000 account records. Most member IP addresses were obfuscated, but over 70,000 exposed real public IPs, along with usernames, emails, registration dates, and other metadata. Also leaked was a PGP private key used by forum admins, which later became accessible after the passphrase was posted online. This breach occurred shortly after law enforcement actions against the forum and the shutdown of its .hn domain following the arrest of its operators. This incident underscores the persistent risk of sensitive data exposure even among cybercriminal communities and highlights evolving law enforcement tactics. The leak fuels ongoing debate over forum honeypots, operational security failures, and the volatility of underground forums, while serving as a timely reminder of the dangers of unprotected data backups and shifting threat actor TTPs.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
MuddyWater Deploys RustyWater RAT: 2026 State-Sponsored Espionage Hits Middle East
Impact· low

MuddyWater Deploys RustyWater RAT: 2026 State-Sponsored Espionage Hits Middle East

In January 2026, the Iranian state-aligned threat actor MuddyWater (also known as Mango Sandstorm and TA450) executed a targeted spear-phishing campaign against diplomatic, maritime, financial, and telecom organizations in the Middle East. Attackers used icon-spoofed phishing emails with malicious Microsoft Word documents, luring victims to enable macros which deployed the RustyWater remote access trojan—a Rust-based modular implant offering asynchronous command-and-control, anti-analysis techniques, registry persistence, and capability to expand post-compromise operations. The campaign reflects MuddyWater’s ongoing evolution from using commercial RATs to custom malware, with RustyWater providing high stealth and operational flexibility. This incident highlights the growing sophistication of state-affiliated threat actors leveraging new malware frameworks and advanced phishing tradecraft. MuddyWater’s rapid shift to Rust-based tooling demonstrates a broader attacker trend toward custom, evasive, and cross-platform implants targeting critical infrastructure and sensitive sectors.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports